惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

宝玉的分享
宝玉的分享
J
Java Code Geeks
S
SegmentFault 最新的问题
L
LangChain Blog
M
MIT News - Artificial intelligence
Stack Overflow Blog
Stack Overflow Blog
IT之家
IT之家
量子位
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
雷峰网
雷峰网
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
The Cloudflare Blog
MongoDB | Blog
MongoDB | Blog
Microsoft Security Blog
Microsoft Security Blog
腾讯CDC
H
Help Net Security
阮一峰的网络日志
阮一峰的网络日志
Jina AI
Jina AI
N
Netflix TechBlog - Medium
A
About on SuperTechFans
博客园 - 叶小钗
美团技术团队
人人都是产品经理
人人都是产品经理
D
DataBreaches.Net

New in Feedly

Automatically collect Splunk Hunting Queries that match your requirements | Feedly Continuously collect Suricata rules matching your requirements | Feedly Enrich and triage Atlassian security releases in the Vulnerability Intel Agent | Feedly Enrich and triage Apple security releases in the Vulnerability Intel Agent | Feedly Feedly completes SOC 2 Type 2 examination | Feedly VirusTotal Integration: Triage IOCs Faster in Feedly | Feedly Feedly Best Practices for CTI Teams | Feedly GreyNoise + Feedly Threat Intelligence: Enriching IoCs | Feedly 7 AI Prompts for Cyberattack Pattern Analysis | Feedly Navigate Feedly Faster with Go To | Feedly Navigate Feedly Faster with Go To Introducing Feedly ThreatBeats: Your daily intel jingles | Feedly Introducing Feedly ThreatBeats: Your daily intel jingles 6 Ways to Automate Threat Intelligence with the Feedly API | Feedly Get threat intelligence to your team fast, in the tools they already use | Feedly Tracking the cyber consequences of geopolitical events | Feedly Analyze your closed-source intelligence in Feedly | Feedly Cyberattack Insights Cards: A dynamic 360° attack view | Feedly Cyberattack Insights Cards: A dynamic 360° attack view 7 ways to prioritize CVEs by how they're exploited | Feedly Ask AI on Threat Actor Insights Cards: Accelerate adversary research with custom queries | Feedly Research IoCs with rich context in seconds, not hours | Feedly Surface top threats in CTI newsletters | Feedly The Scanner: Exploring Potential Futures | Feedly The Radar: Detecting emerging signals | Feedly Prompt Engineering: Newsletter template for real-time phishing trends | Feedly The Monitor: Tracking the known present | Feedly Startup Innovation Radar: A real-time startup database | Feedly The InsightOS architecture | Feedly Feedly MCP Server: Automate CTI workflows with Claude and the Feedly Threat Graph | Feedly
Connect Feedly to OpenCTI: Real-Time Threat Intel, Automa...
Shawn Jaques · 2026-05-29 · via New in Feedly

15-Second summary

OpenCTI consolidates structured threat intelligence into a connected knowledge graph, but getting raw data structured, filtered, and formatted as STIX is the hard part. That's exactly what Feedly does. Feedly's AI monitors thousands of open-source channels, extracts key entities, maps relationships, and delivers clean STIX 2.1 intelligence scoped to your priority intelligence requirements.

With Feedly Threat Intelligence connected to OpenCTI, you can:

  • Automatically populate your knowledge graph with relevant, structured intelligence from thousands of open-source channels.
  • Start investigations with rich context; every entity is enriched with threat actors, TTPs, malware, CVEs, IoCs, and their relationships.
  • Turn raw reports into ready-to-ingest STIX structures, ready for OpenCTI to ingest without cleanup or reformatting.

If you've invested in OpenCTI, Feedly Threat Intelligence helps you turn it into a knowledge graph that's ready for work.

A knowledge graph is only as good as what flows into it

OpenCTI gives CTI teams a powerful foundation for organizing, correlating, and operationalizing threat intelligence. But the platform doesn't collect intelligence on its own. To get the most out of it, teams need a reliable way to feed it with high-quality, relevant data, consistently and at scale.

Most teams rely on IoC-heavy commercial feeds that deliver volume without narrative context, leaving threat actor profiles thin and TTP coverage patchy. Analysts make up the difference manually: reading blogs, pulling reports, and copying data into the platform. Collection consumes hours that should be going toward analysis.

The result is a team spending more time on data management to feed the knowledge graph, than actual analysis.

Feedly Threat Intelligence automates the collection, processing and filtering layers. It continuously monitors thousands of open-source channels and uses AI to extract, structure, and deliver intelligence directly into OpenCTI, so your knowledge graph reflects the current threat landscape without requiring your analysts to build it manually.

Use AI Feeds to focus on what's actually relevant

Not all open-source intelligence is relevant to your organization. Feedly's AI Feeds solve the signal-to-noise problem before anything reaches OpenCTI.

AI Feeds are continuously updated streams of intelligence from over 10,000 open sources, filtered to your organization's specific threat profile: the threat actors targeting your sector, the malware families relevant to your tech stack, and the vulnerabilities that matter to your infrastructure.

You can also define your own trusted sources (specific blogs, vendor advisories, government feeds, or ISACs your team already relies on) and pull structured intelligence exclusively from those channels. This gives you full control over provenance, so your knowledge graph reflects the sources your analysts actually trust.

You can organize AI Feeds or Folders by intel requirements, and the connector continuously pulls from those curated streams. What flows into OpenCTI is curated intelligence scoped to what your team is actually tracking.

Feedly AI Models and the Threat Graph extract and enrich threat data

Feedly's AI Models automatically identify key entities within each article: IoCs (IPs, domains, hashes, URLs, email addresses, and registry keys), CVEs, malware families, threat actors, TTPs, cyberattacks, etc.

The Threat Graph maps the relationships between extracted entities: which threat actor is using which malware, which CVE is being exploited in which campaign, which TTPs are associated with which intrusion set. These relationships are built from the source reporting itself, preserving the analytical context that makes intelligence meaningful.

By the time intelligence leaves Feedly, it's no longer unstructured text. It's a set of connected entities with documented relationships, ready to enrich your knowledge graph rather than just add to it.

Structured for OpenCTI: STIX 2.1 out of the box

OpenCTI is built natively on the STIX 2.1 standard, and so is Feedly's output.

Every piece of intelligence the connector delivers is formatted as a STIX 2.1 bundle: threat actors, malware, TTPs, indicators, vulnerabilities, and the relationships between them are all expressed as proper STIX objects. They map directly to OpenCTI's data model without transformation or cleanup on your end.

This means the intelligence that lands in your knowledge graph is immediately usable, correctly typed, correctly linked, and ready for analysts to pivot on.

Setting up the Integration

Connecting Feedly to OpenCTI takes about 15 minutes.

Integrate

What it looks like in OpenCTI

Once the connector is running, Feedly intelligence appears in OpenCTI as fully structured reports, each one linked to the entities Feedly extracted, with relationships already mapped in the knowledge graph.

Analysts can pivot directly from a Feedly report to the threat actor profile, explore related malware or campaigns, and correlate Feedly-sourced indicators against internal data, all within OpenCTI's graph interface, without re-entering a single data point.

Conclusion

Feedly Threat Intelligence and OpenCTI are built for each other: one collects and structures intelligence from the open web, the other organizes and operationalizes it. Together, they replace a slow, manual collection process with a continuous, automated intelligence pipeline, from open-source data to a knowledge graph to analyst action.

If you've built an OpenCTI deployment and want to keep it current without burning analyst hours on collection, Feedly is the intelligence source that makes it work.

Feedly Threat Intelligence connects with 10+ security solutions

OpenCTI is one of the many integrations available. Start your free trial and see how Feedly Threat Intelligence connects to your CTI workflow.

Try Feedly Threat Intelligence